Jobs › HIPAA
HIPAA Compliance Jobs
HIPAA is the US law governing the privacy and security of protected health information.
The Health Insurance Portability and Accountability Act (HIPAA), through its Privacy Rule, Security Rule, and Breach Notification Rule, sets the federal standard for protecting health information in the United States. It applies to covered entities, health plans, providers, and clearinghouses, and to the business associates that handle protected health information (PHI) on their behalf. The Security Rule requires administrative, physical, and technical safeguards, and the HHS Office for Civil Rights enforces it with investigations and penalties.
In healthcare GRC, HIPAA is the baseline every program is built on, and it is increasingly entangled with AI, as health systems and digital-health companies deploy models on exactly the data HIPAA protects. Roles in this space want people who can run a HIPAA program, manage business-associate risk, and handle breaches, often alongside HITRUST certification.
HIPAA: Frequently Asked Questions
Who must comply with HIPAA?
Covered entities (health plans, health care providers, and clearinghouses) and their business associates that create, receive, maintain, or transmit protected health information.
What are the main HIPAA rules?
The Privacy Rule, the Security Rule, and the Breach Notification Rule, governing the use, protection, and breach reporting of protected health information.
Who enforces HIPAA?
The US Department of Health and Human Services Office for Civil Rights (OCR), which investigates complaints and can impose civil and, in some cases, criminal penalties.
Open HIPAA GRC jobs (44)
Director of Product, Governance & Compliance
Data and AI Risk & Ethics Specialist
Governance, Risk, and Compliance Manager - FedRAMP
Governance, Risk, and Compliance Manager - Privacy
Security Compliance, GRC Engineer
Product GRC Subject Matter Expert, (V4G)
Subject Matter Expert, GTM GRC - V4G
Head of Data Governance - Product Line
GRC Pre-Sales Consultant / Solutions Engineer – EMEA
Privacy Manager
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
VP, Compliance & Risk
Staff+ Software Engineer, Privacy
Privacy Operations Program Manager
Senior Privacy and AI Counsel
Field CISO
Director of IT Governance
Director, Privacy Counsel
Governance, Risk & Compliance Analyst
Virtual CISO & Cybersecurity Practice Lead
Head of Security & AI Governance
Risk Partner
Security, Risk and Compliance Consultant
Director of IT Governance
Director AI Governance & Business Integration
Senior Security Compliance Specialist
Clery Compliance Specialist
Security Compliance Analyst, Privacy
IT Enterprise Risk Analyst
Director of Compliance & Risk Management
Principal, AI Governance
Data and AI Governance Lead, Computing Services
Chief Information Security Officer
Director of Quality and Corporate Compliance
Senior Software Engineer, Trust and Third Party Risk Management
Senior Internal Auditor
Rev Cycle Internal Auditor
HIPAA jobs: what the market looks like right now
A snapshot built from the 44 HIPAA roles currently on this page.
What these roles pay
Of the 44 open HIPAA roles on this page, 14 publish a salary range. Across those:
- Median advertised midpoint: $220k
- Middle half of the market: $145k to $233k
- Full advertised range: $66k to $405k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 8 remote, 1 hybrid, 35 on-site or unstated.
- Seniority mix: mid (21), senior (10), director (7), executive (6)
- Employers hiring more than one: SEI (9), Vanta (5), Penn State University (3), Decagon (2), Albany Medical Center (2)
Skills these postings ask for
- policy and procedure writing
- control testing and evidence collection
- regulatory change management
- SOX and SOC 2 readiness
- issue management and remediation tracking
How to get a compliance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in HIPAA postings to be worth knowing: CCEP, CRCM, CAMS, CIPP/US, AIGP. The certification academy covers what each one actually tests and who it is for.
Hiring for HIPAA?
We have 44 open HIPAA roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts